LEAD-AUDITOR · Question #78
LEAD-AUDITOR Question #78: Real Exam Question with Answer & Explanation
The correct answer is D. There is a nonconformity (NC). The Service Manager does not comply with the software security. The correct option is D. There is a nonconformity (NC). The Service Manager does not comply with the software security management procedure. (Relevant to clause 8.1, control A.8.30). The IT Manager should have approved the test results according to the software security managemen
Question
Exhibit
Options
- AThere is NO nonconformity (NC). The Service Manager makes a good decision to continue the
- BThere is a nonconformity (NC). The organisation and developer do not perform acceptance tests.
- CThere is a nonconformity (NC). The organisation and developer perform security tests that fail.
- DThere is a nonconformity (NC). The Service Manager does not comply with the software security
Explanation
The correct option is D. There is a nonconformity (NC). The Service Manager does not comply with the software security management procedure. (Relevant to clause 8.1, control A.8.30). The IT Manager should have approved the test results according to the software security management procedure, not the Service Manager. The Service Manager's decision to accept the failed security tests also violates the "security-by-design" and "security-by-default" principles that the organization adopted.
Community Discussion
No community discussion yet for this question.
